Legal
Privacy Policy
Last updated 7 July 2026
The short version: we collect the data you give us, the data your browser sends when you use the site, and the data third-party services hand back when you authorize a connection. We use it to run the Service for you. We do not sell it.
1. Who we are
The Green Room (the "Service") is operated by Mike Cameron, based in Alberta, Canada. You can reach us at mike@mikecameron.ca. For the purposes of data-protection law we are the controller of the personal data described below.
2. Information we collect
2.1 Information you provide
- Account. Name, email, password hash, role, profile details.
- Content. Recordings, transcripts, notes, documents, tags, comments, contacts, organizations, opportunities, tasks, invoices, and similar material you upload or create.
- Communications. Messages you send to us, and email you send through the integrated CRM composer.
2.2 Information collected automatically
- Session and device. IP address, browser type, pages visited, timestamps, and the session cookie that keeps you signed in.
- Logs. Server logs of API requests and errors, retained for operational and security purposes.
2.3 Information from connected services
When you connect a third-party service, we receive and store the minimum data needed to operate that connection on your behalf:
- QuickBooks Online. An OAuth refresh token, your QuickBooks company ID ("realm ID"), the connected company's display name, and the date of connection. When you push an invoice we send the customer's name and email, your invoice number, dates, line item descriptions and amounts, tax mappings, and (after a Stripe payment) the payment amount. We cache the QuickBooks Customer ID we created or matched so future invoices to the same contact don't re-query. We do not read your books beyond the lookups required to push invoices and payments (Service Items, Accounts, Tax Codes, and Customer-by-email search).
- Stripe. Connected account ID, account email, charge and payout metadata for invoices billed through the Service.
- Google (Gmail and Calendar). An OAuth refresh token, the email address of the connected account, message headers and short snippets (not full message bodies) for emails matched to your CRM contacts, and calendar event details (title, time, duration, attendees, meeting link) for events synced into your CRM. See section 6 for the full Google-specific disclosures.
- Zoom. An OAuth refresh token and the connected user identity, used to create meeting links when you book one through the Service.
- Dropbox / Google Drive watch folders. Folder IDs and file metadata for files imported into your vault.
3. How we use information
- To provide, maintain, and improve the Service.
- To carry out the specific actions you authorize through a connected integration (for example, pushing an invoice into your QuickBooks file).
- To send transactional email (sign-in links, invoice notifications, calendar confirmations).
- To protect the Service and its members from misuse and security threats.
- To comply with legal obligations.
4. Legal bases
Where the GDPR or equivalent law applies, we rely on:
- Performance of a contract — to provide the Service you have signed up for;
- Consent — for the optional connections you authorize (QuickBooks, Gmail, Calendar, Zoom, Dropbox, Drive). You can withdraw consent by disconnecting at any time;
- Legitimate interests — to keep the Service secure and to improve it;
- Legal obligation — to respond to lawful requests and meet record-keeping requirements.
5. How we share information
We do not sell personal information and we do not share it for advertising. We share it only in these cases:
- With services you have connected. For example, when you push an invoice to QuickBooks Online, the invoice data is sent to Intuit under your authorization.
- With infrastructure providers we use to operate the Service: the hosting provider, the database, transactional-email and file-storage vendors, and the AI providers used for transcription and document extraction. These providers process data on our behalf under written agreements that restrict them to those purposes.
- With other members only when you explicitly share content with them or with a shared vault space they belong to.
- To meet a legal obligation or to protect the rights, property, or safety of members or the public, where required by law.
- In a business transfer. If the Service is acquired or merged, your information may be transferred under the same protections described here.
6. Google user data — specific disclosures
The Service's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practical terms:
- What we access. With your authorization, the Service reads Gmail message metadata and snippets to match email to your CRM contacts, sends email you compose through the CRM composer via your Gmail account, reads and writes calendar events to sync meetings and create bookings you request, and (if you connect a Drive watch folder) reads files in that folder to import them into your vault.
- What we store. Message headers (subject, sender, recipients, thread ID) and short snippets; calendar event details; and file metadata for imported Drive files. We do not store full Gmail message bodies from sync.
- Limited Use. Google user data is used only to provide the CRM, scheduling, and vault features you see in the Service. We do not use it for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide these features or comply with law, and no humans read it except with your consent, for security purposes, or as required by law. Google user data is not used to train generalized artificial-intelligence or machine-learning models.
- Disconnecting. You can disconnect Google at any time from Settings → Connected accounts. Disconnecting revokes our access token at Google and stops all further syncing. Email and calendar records already synced into your CRM remain part of your CRM history; you can delete them individually, or email mike@mikecameron.ca to have all Google-derived data purged within 30 days.
7. QuickBooks Online — specific disclosures
The Service's QuickBooks Online integration follows Intuit's policies for third-party apps. In particular:
- The integration uses Intuit's OAuth 2.0 authorization. We never see, store, or have access to your Intuit username or password.
- We request the
com.intuit.quickbooks.accounting scope, which is the minimum scope needed to create customers, push invoices, look up items / accounts / tax codes, and record payments.
- We use connected QuickBooks data only to operate the features you authorized. We do not use QuickBooks data for marketing, profiling, advertising, or sale to third parties.
- QuickBooks data is stored in our database in the same protected environment as the rest of your Green Room data, behind your account login. Tokens are stored at the row level and rotate per Intuit's policy.
- You can disconnect QuickBooks at any time from Settings → Connected accounts. Disconnecting revokes our refresh token at Intuit on a best-effort basis, clears the per-contact QuickBooks Customer ID cache, and stops further data exchange. Data already written into your QuickBooks file remains in your QuickBooks file and is governed by Intuit's terms.
- To request deletion of QuickBooks-related data we hold about you, email mike@mikecameron.ca and we will action it within 30 days.
8. Data retention
We keep account and content data for as long as your account is active. When you close your account we delete or anonymize personal data within 90 days, except where we are required to keep it longer for tax, accounting, or legal reasons. Server logs are retained for up to 90 days. Backups are retained on a rolling basis and overwritten in the normal course.
9. Security
We protect data in transit with TLS and at rest with the access controls of our hosting and storage providers. Passwords are hashed with bcrypt. OAuth refresh tokens are stored in the member's database row and are only accessible to server-side code. No system is perfectly secure; we do our best, and we tell you promptly if we learn of a breach that affects you.
10. International transfers
The Service is operated from Canada. Some of the infrastructure providers we use may store or process data in other countries, including the United States. Where required, we rely on contractual safeguards (such as the EU Standard Contractual Clauses) for those transfers.
11. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct it if it is wrong;
- delete it, subject to legal exceptions;
- export it in a portable format;
- object to or restrict certain processing;
- withdraw consent for connected integrations at any time.
To exercise any of these rights, email mike@mikecameron.ca. We will respond within 30 days. If you are in the EU/UK and believe we have not handled your data properly, you can lodge a complaint with your local data-protection authority.
12. Children
The Service is intended for adults. We do not knowingly collect personal information from children under 16. If you believe we have, contact us and we will delete it.
13. Cookies
We use a single first-party session cookie to keep you signed in. We do not use third-party advertising or analytics cookies on the application surface. Public pages may include first-party analytics in the future; this policy will be updated if that changes.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date above. Material changes will be communicated through the Service or by email.
15. Contact
Questions, requests, or complaints about this Privacy Policy can be sent to mike@mikecameron.ca.